SSL Root Certificate, Client Certificate, and 2FA

Hi Experts need your kind help.

Setting up two factor authentication for VPN users using SSL Certificate Authentication + OTP authentication. OTP has been completed and it works with VPN appliance, but when adding policy Certificate authentication before OTP it fails.

I have created ROOT CA and also client Certificate for authentication, but it fails.

CA will be offline.(Standalone ROOT CA)
Client certificate installation manual.
Root CA will be stored in F5 VPN Appliance.(Hardware)
Client certificate will be installed in mobile users laptops.
Each time they connect VPN IP, the F5 VPN appliance will check for certificate and then allow for OTP authentication.

if you are doing a machine cert check using F5 APM then you need to make sure that that the imported certificate is at the right place. Note Machine cert is only good for PC but not for mobile devices.

Also understand that machine cert is only (currently) supported for PC and requires the Edge client, you should probably stick with the default "MY" value. There is also debug that can enable logging for APM and watch /var/log/apm while testing. Devcentral is a good place to post further clarification as the F5 expert is there as below example ...

all links given to me greatly helped to get in F5 forums...
found the issues at CA side and also F5 configuration side....
it took so long to solve..however links steps given helped to navigate the issue and solve it.
thanks....